Home Malware Programs Backdoors Win32.Gbot.lwp

Win32.Gbot.lwp

Posted: July 11, 2011

Win32.Gbot.lwp is a Trojan that can infect your PC for a wide array of purposes that potentially include creating security holes, installing other injurious programs, changing system settings for the worse, enabling remote attacker-based harm and steal private information. Since Win32.Gbot.lwp may not give any obvious visual clues to being present, you should take care to practice preventative security to stop a Win32.Gbot.lwp infection from happening in the first place. In spite of Win32.Gbot.lwp's low-key nature, Win32.Gbot.lwp is a very real and very dangerous threat to your PC's safety and the privacy of the information that's stored on your PC. As such you should waste no time in deleting Win32.Gbot.lwp with a decent anti-virus program.

That Link from a Friend May Have Win32.Gbot.lwp at the Other End

Win32.Gbot.lwp has been reported to use social networking to proliferate. Try to avoid clicking on links and files, even if they're sent by known acquaintances, until you've verified that they're safe. Many Trojans and similar PC threats will spoof the name of a known contact, and some may use bots to imitate conversation with realism. Possible Win32.Gbot.lwp infection vectors can include websites, email and instant messages.

Most detections of Win32.Gbot.lwp have only been seen in July of 2011, which makes Win32.Gbot.lwp a very new threat. Update your anti-virus software for new threats and keep your browser and other security-related applications updated to minimize any possible Win32.Gbot.lwp attack.

How Win32.Gbot.lwp Can Be Just a Funnel to Other Problems

Although Win32.Gbot.lwp's full capabilities currently are poorly-defined, Trojan threats that are similar to Win32.Gbot.lwp are known to be able to perform some or sometimes all of the attacks noted here:

  • Win32.Gbot.lwp may launch itself without permission when Windows loads, and keep running on your PC background. This can use up noticeable system resources and allows Win32.Gbot.lwp to engage in more directly hostile behavior at any time.
  • Win32.Gbot.lwp may install other harmful applications, with a list that can range from password-grabbing spyware to rogue security software and Remote Administration Tools. Some of these programs, such as spyware and RATs, will compromise your PC's privacy and security while not giving off obvious signs that your computer is being harmed at all.
  • Your system settings may also be changed by the presence of Win32.Gbot.lwp, with network and security-related settings being especially at risk. Keeping an eye on open ports, exceptions in your firewall and other network security-related issues can help you spot a Win32.Gbot.lwp attack.
  • Just having Win32.Gbot.lwp on your computer can also be a road to having your computer controlled by criminals. Remote-based attacks that use Trojans like Win32.Gbot.lwp are capable of almost any type of harmful behavior but are best known for being the root of Denial-of-Service crimes.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\google\GoogleUpdate.exe
    2 %Windir%\Config\conime.exe
    3 RANDOM CHARACTERS.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\WordpaHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\IPHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\OptionsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\RTFHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\SettingsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\TextHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Word6HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\WriteHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XTray.exe
Loading...